LibreHealth EHR Base 2.0.0 allows gacl/admin/acl_admin.php return_page XSS.
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Link | Tags |
---|---|
https://github.com/LibreHealthIO/lh-ehr/tags | release notes |
https://gitlab.com/librehealth/ehr/lh-ehr/-/tags | release notes |
https://nitroteam.kz/index.php?action=researches&slug=librehealth2_r | third party advisory exploit |